Описание
Security update for nodejs10
This update for nodejs10 fixes the following issues:
- CVE-2023-44487: Fixed the Rapid Reset attack in nghttp2. (bsc#1216190)
Список пакетов
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS
nodejs10-10.24.1-150000.1.62.3
nodejs10-devel-10.24.1-150000.1.62.3
nodejs10-docs-10.24.1-150000.1.62.3
npm10-10.24.1-150000.1.62.3
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
nodejs10-10.24.1-150000.1.62.3
nodejs10-devel-10.24.1-150000.1.62.3
nodejs10-docs-10.24.1-150000.1.62.3
npm10-10.24.1-150000.1.62.3
SUSE Linux Enterprise Server 15 SP1-LTSS
nodejs10-10.24.1-150000.1.62.3
nodejs10-devel-10.24.1-150000.1.62.3
nodejs10-docs-10.24.1-150000.1.62.3
npm10-10.24.1-150000.1.62.3
SUSE Linux Enterprise Server 15 SP2-LTSS
nodejs10-10.24.1-150000.1.62.3
nodejs10-devel-10.24.1-150000.1.62.3
nodejs10-docs-10.24.1-150000.1.62.3
npm10-10.24.1-150000.1.62.3
SUSE Linux Enterprise Server for SAP Applications 15 SP1
nodejs10-10.24.1-150000.1.62.3
nodejs10-devel-10.24.1-150000.1.62.3
nodejs10-docs-10.24.1-150000.1.62.3
npm10-10.24.1-150000.1.62.3
SUSE Linux Enterprise Server for SAP Applications 15 SP2
nodejs10-10.24.1-150000.1.62.3
nodejs10-devel-10.24.1-150000.1.62.3
nodejs10-docs-10.24.1-150000.1.62.3
npm10-10.24.1-150000.1.62.3
openSUSE Leap 15.4
nodejs10-10.24.1-150000.1.62.3
nodejs10-devel-10.24.1-150000.1.62.3
nodejs10-docs-10.24.1-150000.1.62.3
npm10-10.24.1-150000.1.62.3
Ссылки
- Link for SUSE-SU-2023:4295-1
- E-Mail link for SUSE-SU-2023:4295-1
- SUSE Security Ratings
- SUSE Bug 1216190
- SUSE CVE CVE-2023-44487 page
Описание
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:nodejs10-10.24.1-150000.1.62.3
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:nodejs10-devel-10.24.1-150000.1.62.3
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:nodejs10-docs-10.24.1-150000.1.62.3
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:npm10-10.24.1-150000.1.62.3
Ссылки
- CVE-2023-44487
- SUSE Bug 1216109
- SUSE Bug 1216123
- SUSE Bug 1216169
- SUSE Bug 1216171
- SUSE Bug 1216174
- SUSE Bug 1216176
- SUSE Bug 1216181
- SUSE Bug 1216182
- SUSE Bug 1216190